PT-2026-86684 · Linksys · Re7000

·

CVE-2026-86299

·

Published

2026-09-07

·

Updated

2026-09-08

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform event pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/pingTestTimes results in os command injection. The attack can be launched remotely. The exploit is now public and may be used.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86299

Affected Products

Re7000